Virtual Information Technology logo
Virtual Information TechnologyPosted 1 month ago

Security Engineer

$140,000–$160,000 year

HybridNorth Sydney, New South Wales, Australia

Full Time

Job Summary

Build, test, and maintain high-fidelity detection rules across Elastic SIEM and Microsoft Sentinel, focusing on reducing noise and improving signal quality. Advance detection-as-code capability through version-controlled rules, automated testing pipelines, and CI/CD-driven deployment of detection content. Support the analyst team with alert triage, escalation, and hands-on incident response during high-severity events while conducting proactive threat hunts informed by threat intelligence and MITRE ATT&CK. Tune existing detections and SIEM data pipelines, write Python tooling to automate repetitive tasks, and collaborate with infrastructure teams to ensure logging coverage across AWS, Azure, and GCP environments. Engage directly with customers to understand their telemetry sources and enable the SOC to leverage AI for efficiency.

Required Qualifications

  • Demonstrated experience in a security engineering, detection engineering, or senior SOC role
  • Proficiency in Python for scripting, automation, and tooling development
  • Solid understanding of cloud infrastructure (AWS, Azure) and the security telemetry these platforms produce
  • Experience with detection-as-code practices, CI/CD pipelines, and version control (Git)
  • Familiarity with MITRE ATT&CK and structured approaches to threat modelling and adversary emulation
  • An engineering mindset above all - you attack problems based on their unique circumstances, think in systems, and build scalable solutions

Desired Qualifications

  • Strong hands-on experience with Elastic SIEM and/or Microsoft Sentinel
  • Familiarity with leading XDR platforms, Microsoft Defender, Trend Micro Vision One, Crowdstrike
  • Experience with SOAR platforms, log enrichment, or data pipeline engineering (e.g., Logstash, Cribl)
  • Relevant certifications (e.g., GCIA, GCIH, GCED, AZ-500, AWS Security Specialty)
  • Contributions to open-source security tooling or community detection rule sets

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce